Skip to main content
Cloud / STACKIT / Products / STACKIT Confidential Kubernetes - Encrypted Containers

STACKIT Confidential Kubernetes - Encrypted Containers

STACKIT Confidential Kubernetes: hardware-isolated Kubernetes clusters with remote attestation for regulated workloads.

Confidential
Pricing Model Individual quote on request, customer-specific provisioning; since 01/12/2025 compute resources and the associated license are billed as separate SKUs (previously a combined product)
Availability German STACKIT data centers
Data Sovereignty 100% German data centers, GDPR compliant
Reliability SLA as published by the provider SLA

What is STACKIT Confidential Kubernetes?

STACKIT Confidential Kubernetes is a confidential computing platform that allows containerized applications to run in a cluster shielded from the underlying cloud infrastructure. All Kubernetes nodes run as Confidential Virtual Machines (CVMs) with hardware-based memory encryption (runtime encryption). This keeps data protected even while it is being processed in memory and allows its integrity to be cryptographically verified.

Core Features

  • Hardware-isolated cluster nodes based on Confidential Virtual Machines
  • Transparent encryption of network and storage
  • Remote attestation for individual nodes joining the cluster
  • Proof of integrity for the entire cluster via a hardware-bound certificate
  • Automated, transparent key management within the isolated environment

Typical Use Cases

Regulated industries: Healthcare, finance, and the public sector with strict data protection and auditability requirements.

Cloud migration of sensitive workloads: Organizations moving on-premises workloads with private-cloud-level security requirements into the public cloud.

Trustworthy SaaS offerings: Providers who want to cryptographically prove the isolation and integrity of their platform to customers.

Benefits

  • Closes the gap between encryption at rest/in transit and encryption during processing
  • Operated in German STACKIT data centers, GDPR compliant
  • Verifiable security through remote attestation rather than pure trust in the provider
  • Enterprise-ready DevOps features (high availability, upgrades, infrastructure-as-code support)

Integration with innFactory

As an official STACKIT partner, innFactory supports the introduction of Confidential Kubernetes: from architecture and migration of existing workloads to ongoing operations and cost optimization.

Available Tiers & Options

Typical Use Cases

Regulated industries (healthcare, finance, public sector)
Migrating sensitive on-premises workloads to the cloud
Trustworthy SaaS offerings with verifiable isolation
Workloads with strict data protection and compliance requirements

Frequently Asked Questions

What is STACKIT Confidential Kubernetes?

A confidential computing platform that lets customers run containerized applications in a cluster shielded from the underlying cloud infrastructure at the hardware level. All Kubernetes nodes run as Confidential Virtual Machines (CVMs).

How does the encryption work?

All Kubernetes nodes run inside encrypted CVMs. Network and storage are encrypted transparently, protecting data at rest, in transit, and while being processed in memory.

What does STACKIT Confidential Kubernetes cost?

The service is currently offered on a customer-specific basis; a concrete quote is obtained through STACKIT sales. Since 1 December 2025, STACKIT bills compute resources and the associated license as separate SKUs instead of a single combined product.

How can I verify the integrity of my cluster?

Each new node is verified via remote attestation before it is granted access to the cluster. The integrity of the entire cluster can additionally be proven using a hardware-bound certificate.

Where can I find the official documentation?

STACKIT currently does not publish public technical documentation for Confidential Kubernetes in its docs portal; the former "Confidential Computing" category is no longer available there. The official product page is the authoritative source, and technical details are available via STACKIT sales.

What use cases fit Confidential Kubernetes?

Regulated industries with strict compliance requirements, migrating sensitive workloads to the cloud, and providers who want to increase the trustworthiness of their SaaS offering through verifiable isolation.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Ready to start with STACKIT Confidential Kubernetes - Encrypted Containers?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation